LWN.net Logo

squid: denial of service

Package(s):squid CVE #(s):CVE-2011-4096
Created:November 18, 2011 Updated:January 6, 2012
Description: From the Red Hat bugzilla:

An invalid free flaw was found in the way Squid proxy caching server processed DNS requests, where one CNAME record pointed to another CNAME record pointing to an empty A-record. A remote attacker could issue a specially-crafted DNS request, leading to denial of service (squid daemon abort).

Alerts:
CentOS CESA-2011:1791 2011-12-22
Oracle ELSA-2011-1791 2011-12-17
Mandriva MDVSA-2011:193 2011-12-27
Scientific Linux SL-squi-20111206 2011-12-06
Red Hat RHSA-2011:1791-01 2011-12-06
Fedora FEDORA-2011-15233 2011-11-02
Fedora FEDORA-2011-15256 2011-11-02
Debian DSA-2381-1 2012-01-06
openSUSE openSUSE-SU-2012:0213-1 2012-02-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds